็†ฑ้–€ๅˆ†้กž
 ่ผ‰ๅ…ฅไธญ…
็›ฎ้Œ„

๐Ÿงฑ FortiGate CLI ็ฎก็†่ˆ‡่จบๆ–ทๅ…จๆ”ป็•ฅ:ๅธณ่™Ÿ、ไป‹้ข、Policy、่ทฏ็”ฑ่ˆ‡ๅฐๅŒ…ๅˆ†ๆžๅฎŒๆ•ดๆŒ‡ไปคๆ•™ๅญธ

    FortiGate ๆ˜ฏไผๆฅญ็ถฒ่ทฏไธญๆœ€ๅธธ่ฆ‹็š„้˜ฒ็ซ็‰†ไน‹ไธ€, ๆไพ›ๅผทๅคง็š„ๅฎ‰ๅ…จ็ญ–็•ฅ、ๆต้‡ๆŽง็ฎก่ˆ‡่จบๆ–ทๅŠŸ่ƒฝ。 ๆœฌ็ฏ‡ๆ•ด็† CLI(Command Line Interface) ็š„ๅฎŒๆ•ดๆŒ‡ไปค้›†, ๅพžๅธณ่™Ÿ่ˆ‡ไป‹้ข็ฎก็†ๅˆฐๅฐๅŒ…ๅˆ†ๆž,ๅ”ๅŠฉๅทฅ็จ‹ๅธซๅฟซ้€ŸๆŽŒๆก็ณป็ตฑ้‹ไฝœ่ˆ‡้™ค้ŒฏๆŠ€ๅทง。


    ๐Ÿ‘ค ไธ€、ๅธณ่™Ÿ่ˆ‡็ณป็ตฑ็ฎก็†

    ็”จๆ–ผๆชข่ฆ–็ณป็ตฑ็‹€ๆ…‹、็‰ˆๆœฌ、ๅธณ่™Ÿ่ˆ‡ๆฌŠ้™่จญๅฎš:

    get system status
    get system performance status
    config system admin
    show
    end
      

    ๅปบ็ซ‹ๆ–ฐ็ฎก็†ๅธณ่™Ÿ:

    config system admin
    edit admin2
    set password MyStrongPassword
    set accprofile super_admin
    set vdom root
    next
    end
      
    ✅ ๅปบ่ญฐ: - ไฝฟ็”จ set accprofile ๆŒ‡ๅฎšๆฌŠ้™ๅฑค็ดš(ๅฆ‚ read_onlysuper_admin)。 - ้–‹ๅ•Ÿ two-factor ๅฏๆๅ‡ๅฎ‰ๅ…จๆ€ง。

    ๐ŸŒ ไบŒ、็ถฒ่ทฏไป‹้ข่ˆ‡ VLAN ่จญๅฎš

    ๆŸฅ็œ‹็ถฒ่ทฏไป‹้ข่ˆ‡็‹€ๆ…‹:

    show system interface
    get system interface physical
    diagnose hardware deviceinfo nic port1
    get system arp
      

    ่จญๅฎš้œๆ…‹ IP ๆˆ– VLAN:

    config system interface
    edit port1
    set ip 192.168.1.1/24
    set allowaccess ping https ssh http
    set alias LAN
    next
    edit vlan10
    set vdom root
    set interface port1
    set vlanid 10
    set ip 10.10.10.1/24
    next
    end
      

    ✅ ๆชขๆŸฅ: ไฝฟ็”จ execute ping 8.8.8.8 ๆธฌ่ฉฆๅค–้ƒจ้€ฃ็ทšๆ˜ฏๅฆๅฏ้”。


    ๐Ÿงฑ ไธ‰、้˜ฒ็ซ็‰† Policy ็ฎก็†

    ๅˆ—ๅ‡บ็พๆœ‰็š„ Policy ่ˆ‡่ฉณ็ดฐๅ…งๅฎน:

    show firewall policy
    show firewall policy 10
      

    ๅปบ็ซ‹ๆ–ฐ้˜ฒ็ซ็‰† Policy:

    config firewall policy
    edit 10
    set name Allow-Web
    set srcintf "port1"
    set dstintf "port2"
    set srcaddr "all"
    set dstaddr "all"
    set service "HTTP" "HTTPS"
    set action accept
    set schedule "always"
    set nat enable
    next
    end
      

    ✅ ๅปบ่ญฐ:

    • Policy ้ †ๅบๅฝฑ้Ÿฟๆต้‡ๅŒน้…,็ขบไฟๅ…่จฑ่ฆๅ‰‡ๅœจ้˜ปๆ“‹่ฆๅ‰‡ไน‹ๅ‰。
    • ๅฏ็”จ diagnose sys session list | grep x.x.x.x ๆŸฅ็œ‹ๆ˜ฏๅฆ่ขซๅŒน้…。

    ๐Ÿ›ฐ️ ๅ››、่ทฏ็”ฑๆชขๆŸฅ่ˆ‡ๆต้‡่ฟฝ่นค

    ๆŸฅ็œ‹้œๆ…‹่ˆ‡ๅ‹•ๆ…‹่ทฏ็”ฑ่กจ:

    get router info routing-table all
    show router static
    get router info routing-table details 10.1.1.0
      

    ่ฟฝ่นคๅฐๅŒ…่ทฏๅพ‘:

    execute traceroute 8.8.8.8
    execute ping 192.168.1.10
      

    ✅ ๅฐๆŠ€ๅทง: ่‹ฅๆ‰พไธๅˆฐ่ทฏ็”ฑ,ๅฏๆชขๆŸฅ Default Route ๆˆ– Policy ๆ˜ฏๅฆๆ”พ่กŒ。


    ๐Ÿ“ก ไบ”、ๅฐๅŒ…ๅˆ†ๆž่ˆ‡ Debug Flow

    ๆœ€ๅธธ็”จ็š„่จบๆ–ท่ˆ‡ๅฐๅŒ…่ฟฝ่นคๆŒ‡ไปค:

    diagnose sniffer packet any '(src host 10.1.1.10 or dst host 192.168.10.20)' 4 0
    diag debug enable
    diag debug flow show console enable
    diag debug flow filter addr 192.168.1.100
    diag debug flow trace start 100
      

    ๅœๆญข debug:

    diag debug disable

    ✅ ๅปบ่ญฐ:

    • sniffer packet ้ฉๅˆๅฟซ้€Ÿ่ง€ๅฏŸๅฏฆ้ซ”ไป‹้ขๆต้‡。
    • debug flow ๅฏ็ฒพๆบ–่ฟฝ่นค Policy ่ˆ‡ NAT ๆตๅ‘。
    • ๅฏๆ–ผ GUI → Packet Capture ๅŒฏๅ‡บ .pcap ๆช”ๅˆ†ๆž。

    ๐Ÿงฐ ๅ…ญ、็ณป็ตฑ่จบๆ–ท่ˆ‡ๆ•ˆ่ƒฝ็›ฃๆŽง

    ๅณๆ™‚็›ฃๆŽง็ณป็ตฑๆ•ˆ่ƒฝ่ˆ‡้€ฃ็ทš็‹€ๆณ:

    get system performance status
    diag sys top
    diag sys session stat
      

    ๆธ…้™ค้Žๅคš session:

    diag sys session clear

    ✅ ๆ็คบ: ่‹ฅ CPU ๆˆ–่จ˜ๆ†ถ้ซ”ไฝฟ็”จ็އ็•ฐๅธธ,ๅฏ็”จ diag sys top ่ง€ๅฏŸๅ•้กŒ้€ฒ็จ‹。


    ๐Ÿ“˜ ็ต่ชž

    ็†Ÿๆ‚‰ FortiGate CLI ๆŒ‡ไปค,่ƒฝ่ฎ“็ถฒ็ฎก่ˆ‡่ณ‡ๅฎ‰ๅทฅ็จ‹ๅธซๆ›ดๅฟซๅฎšไฝๅ•้กŒ、้ฉ—่ญ‰่จญๅฎšไธฆ้€ฒ่กŒๆ•ˆ่ƒฝ่ชฟๆ•ด。 ็„ก่ซ–ๆ˜ฏๅธณ่™Ÿ็ฎก็†、Policy ๅปบ็ฝฎๆˆ–ๅฐๅŒ…ๅˆ†ๆž,CLI ็š†ๆไพ›ๆฏ” GUI ๆ›ด็ดฐ็ทป็š„่จบๆ–ท่ƒฝๅŠ›。 ๅปบ่ญฐๆ—ฅๅธธ็ถญ้‹ไธญ,ๅฎšๆœŸๅฐŽๅ‡บ่จญๅฎšๅ‚™ไปฝ่ˆ‡็›ฃๆŽงๆŒ‡ไปค่ผธๅ‡บ,็ขบไฟ็ถฒ่ทฏ็ฉฉๅฎš่ˆ‡ๅฎ‰ๅ…จ。

    — WWFandy・็ถฒ่ทฏ่ˆ‡่ณ‡ๅฎ‰็ญ†่จ˜

    LIST 7_DAYS 5 LIST ALL_TIME 5
    ๐Ÿ”— ๅˆ†ไบซ้€™็ฏ‡ LINE Facebook X

    ๆฒ’ๆœ‰็•™่จ€:

    ๅผต่ฒผ็•™่จ€

    ๅญ—็ดš